RAEDiff: Diffusion Models Enable Self-Generation and Self-Recovery of Reversible Adversarial Examples
摘要
Currently, Reversible Adversarial Example (RAE) techniques primarily focus on methods based on Reversible Data Hiding (RDH), which typically rely on auxiliary information for adversarial sample recovery, posing risks of image loss due to information transmission. Inspired by recent advancements in diffusion models, we identify two key characteristics of diffusion models: the generation of content is governed by the Gaussian distribution of the diffusion process, and well-trained diffusion models possess robust image restoration capabilities. In selecting the diffusion model, we opt for DDPM to explore the controllability and effectiveness of RAE generation based on diffusion models. Consequently, we propose a novel framework for RAE generation based on diffusion models, termed RAEDiff that achieves self-generation and self-recovery of RAE for the first time. These benefits are attained without the need for additional auxiliary information, thereby enhancing the controllability and effectiveness of RAE in practical applications. To the best of our knowledge, this marks the first introduction of diffusion models into the field of RAE. Comprehensive experiments are conducted to demonstrate the outstanding performance of RAEDiff in terms of adversarial capability, restoration capability, and robustness.